The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an IDAT chunk with a length of zero.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: certcc

Published: 2014-02-27T20:00:00

Updated: 2014-03-14T14:57:00

Reserved: 2013-12-05T00:00:00


Link: CVE-2014-0333

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2014-02-27T20:55:04.850

Modified: 2014-03-26T04:56:09.813


Link: CVE-2014-0333

JSON object: View

cve-icon Redhat Information

No data.

CWE